PT-2025-41710 · Unknown · Rainygao Docsys

Rainygao

+1

·

Published

2025-10-12

·

Updated

2025-10-12

·

CVE-2025-11630

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RainyGao DocSys versions up to 2.02.36
Description A flaw exists in the File Upload component of RainyGao DocSys. The updateRealDoc function within the /Doc/uploadDoc.do file is susceptible to path traversal due to manipulation of the path argument. This issue can be exploited remotely. The exploit is publicly available.
Recommendations Versions prior to 2.02.36 should be updated.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-11630

Affected Products

Rainygao Docsys